Impact
The Booking Package WordPress plugin before version 1.7.25 accepts payment amounts supplied by the client without server‑side validation and calculates the expected charge using only those attacker‑supplied values. As a result, an unauthenticated user can submit requests that cause the system to record a payment for a fraction of a service’s real price, allowing the attacker to defraud the site or its customers.
Affected Systems
Any WordPress installation deploying the Booking Package plugin of a version older than 1.7.25 is affected. The vulnerability resides in the plugin’s payment processing code that handles service and option cost parameters without verifying them against the stored prices.
Risk and Exploitability
The flaw can be exploited without authentication, making it globally reachable via normal HTTP requests. The data does not include a CVSS score or EPSS value, but the financial implications and lack of access control suggest a high‑severity risk. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (KEV). An attacker can manipulate the amount charged while the system records the transaction as legitimate, potentially leading to significant revenue loss.
OpenCVE Enrichment